Data Processing Addendum

Last updated: · Version 2026-09-27

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Customer”) and Ivorn (“Ivorn”), the provider of Omnihorn. It applies wheneverIvorn processes personal data on your behalf, and it takes effect automatically when you accept the Terms — no signature is needed. If you need a countersigned copy, write to legal@unicornfamily.dev.

1. Roles

  • For End User data — data sent by the installers of your apps (section 2) — you are the controller and Ivorn is your processor.
  • For your account, workspace and billing data, Ivorn is an independent controller, as described in the Privacy Policy. This DPA does not apply to that data.

2. Details of the processing

Subject matterDelivering your application builds to End Users and giving you install and update analytics.
DurationFor as long as you use Omnihorn, plus the deletion period in section 8.
Nature and purposeReceiving, storing, aggregating and displaying update checks and install/update/uninstall events; logging access to private channels.
Data subjectsPeople who install and run your applications (End Users).
Personal dataA random device ID generated by the installer; app, channel and build identifiers; platform and operating-system version; event type and time; for private channels, which channel token was used; and, when an End User uninstalls through the installer and chooses to answer, the reason they pick from a fixed list and an optional short note (up to 200 characters) that they type themselves. IP addresses are not stored in the database; they appear only in reverse-proxy logs.
Special categoriesNone. You must not configure Omnihorn to send special-category data. The uninstall note is free text written by the End User: do not ask End Users to include personal details in it, and treat what you read there as personal data if it identifies anyone.

3. Ivorn's obligations as processor

Ivorn will:

  • process End User data only on your documented instructions — these Terms, this DPA and your configuration ofOmnihorn — unless the law requires otherwise, in which case Ivorn will tell you first where the law allows;
  • ensure that everyone authorised to process the data is bound by confidentiality;
  • implement the security measures in section 7;
  • engage subprocessors only as described in section 5;
  • help you, taking into account the nature of the processing, to respond to End Users exercising their rights and to meet your obligations on security, breach notification, impact assessments and prior consultation;
  • notify you of a personal data breach as described in section 6;
  • delete or return End User data at the end of the service, as described in section 8;
  • make available the information needed to demonstrate compliance with this DPA, as described in section 9.

4. Your obligations

You are responsible for having a lawful basis for the processing, for informing your End Users (for example in your application’s privacy notice) and for the lawfulness of your instructions.

5. Subprocessors

You authorise Ivorn to use the subprocessors below. Ivorn imposes data-protection obligations on each of them that are no less protective than this DPA, and remains responsible for their performance.

Current subprocessors

ProviderPurposeLocationData involved
Self-hosted infrastructure (operated by us)Application servers, PostgreSQL databases, Redis, message queue, and MinIO object storage for build files; reverse proxy and log system.[[PLACEHOLDER: country where the current self-hosted server is located]]All service data
ResendTransactional email delivery (sign-in links, quota warnings).USACustomer email address, email content
WayForPayCard payments for buyers in Ukraine.UkrainePayer email, order and payment data
SentryCrash and error monitoring for the Omnihorn installer. Listed ahead of use: not yet enabled for any compiled installer.USA / European UnionError messages, stack traces, the same random device ID sent with update checks — no name, email or IP address
TailscalePrivate network used by our staff to reach the administration site and by our installer build machine to reach our infrastructure.[[PLACEHOLDER: Tailscale processing location — check its DPA]]Network connection metadata of our own devices; service traffic is end-to-end encrypted
GitHub (including GitHub Container Registry)Hosting of our own source code, build pipeline and container images.USANone of your data or End User data

Planned — will be added before launch

These providers are not used today. They will be added when the corresponding change goes live, with notice as described below.

ProviderPurposeLocationData involved
HetznerVirtual servers replacing the current self-hosted server.Germany / FinlandAll service data
CloudflareDNS, content delivery of build files, and R2 object storage.Global network; USABuild files, download requests (IP address, user agent)
PaddleMerchant of record for purchases outside Ukraine: checkout, tax, invoicing, refunds.United KingdomBuyer name, email, billing address, country, tax ID, payment data

Changes. Ivorn will update this list and notify customers by email or in the dashboard at least [[PLACEHOLDER: subprocessor change notice period — e.g. 30 days]] before a new subprocessor starts processing End User data. You may object on reasonable data-protection grounds by writing to privacy@unicornfamily.dev within that period; if we cannot address the objection, you may cancel the affected service and receive a pro-rata refund of prepaid fees for it.

6. Personal data breaches

Ivorn will notify you without undue delay, and in any case within [[PLACEHOLDER: breach notification window — e.g. 72 hours]], after becoming aware of a personal data breach affecting End User data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where not all of this is available at once, Ivorn will provide it in phases.

7. Security measures

The technical and organisational measures in place today are:

  • TLS for all public traffic to the dashboard, API and update service.
  • Every build manifest signed with a per-app Ed25519 key and verified by the installer before any file is applied; each downloaded file verified against its SHA-256 hash.
  • App signing keys encrypted at rest with a master key, or optionally held under a cloud key-management service.
  • Channel tokens and API keys stored only as SHA-256 hashes; private channels can also require a password, stored as an argon2id hash.
  • Per-workspace isolation: every query is scoped to the workspace, and a workspace can only reference stored files it uploaded itself; download links are short-lived and signed.
  • The update service reads only the application database; account and billing data sit in a separate database it cannot reach.
  • Staff accounts use argon2id-hashed passwords with lock-out after repeated failures, separate credentials from customer accounts, role-based permissions and an audit log of every administrative action. The administration site is reachable only over a private network.
  • Uploads may be scanned for malware before they are published.

Ivorn may improve these measures over time but will not materially reduce the overall level of protection.

8. Deletion at the end of the service

At the end of the service, or earlier on your written request to privacy@unicornfamily.dev, Ivorn deletes the End User data it holds for you from its active systems, unless the law requires it to keep it. Deleting an app in the dashboard deactivates it but does not yet purge its End User data automatically, and automatic retention schedules for analytics events and access logs have not been introduced; until they are, that data is kept until it is deleted on request or the account is closed. Copies in logs are removed as those logs are rotated.

9. Audits

On written request, not more than once a year unless a breach or a supervisory authority requires more, Ivornwill answer reasonable written questions about its compliance with this DPA and provide relevant documentation. Any on-site audit must be agreed in advance, at your cost, and subject to confidentiality.

10. International transfers

Ivorn operates from Ukraine, and subprocessors may process data in the European Union, the United Kingdom and the United States. Where End User data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, the parties rely on [[PLACEHOLDER: SCC module/version and transfer mechanism]], which are incorporated into this DPA by reference, with Ivorn as data importer.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of End User data, this DPA prevails; the standard contractual clauses, where they apply, prevail over both.